2.6.4 Enable Firewall Stealth Mode

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

While in Stealth mode the computer will not respond to unsolicited probes, dropping that traffic.

[http://support.apple.com/en-us/HT201642](http://support.apple.com/en-us/HT201642)

Rationale:

Stealth mode on the firewall minimizes the threat of system discovery tools while connected to a network or the Internet.

Solution

Perform the following to implement the prescribed state:

1. Open System Preferences
2. Select Security & Privacy
3. Select Firewall Options
4. Select Enable stealth mode

Alternatively:

1. Run the following command in Terminal:

sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setstealthmode on

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: Unix

Control ID: 25003c7ea1e711b4df9ca06ad1e931536916e54f53fe56dafedfbea86ae33677